Vulnerabilities exploitable today
369,308in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,142
- High7,641
- Medium5,645
- Low547
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-14088—20.4%
——6——CVE-2022-42811—20.4%
——6——CVE-2017-18780—20.4%
——6——CVE-2026-480535.8 MED20.4%
——6Kolibri is an offline-first education platform. Prior to version 0.19.4, several Kolibri API endpoints accept an unvalidated `baseurl` parameter and fetch attacker-controlled URLs from the Kolibri server, reflecting the response body back to the caller. The original report identified two endpoints on the `RemoteFacilityUser*` viewsets; remediation review found two further reflection points on the same pattern. The GET endpoint was unauthenticated. Version 0.19.4 fixes the vulnerability.20dCVE-2025-4205—20.4%
——6——CVE-2026-177754.3 MED20.4%
——6Inappropriate implementation in PresentationAPI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)33dCVE-2025-36897—20.4%
——6——CVE-2026-178294.3 MED20.4%
——6Insufficient policy enforcement in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)34dCVE-2026-177884.3 MED20.4%
——6Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)33dCVE-2026-479435.4 MED20.4%
——6Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.10dCVE-2020-12330—20.4%
——6——CVE-2019-9529—20.4%
——6——CVE-2026-47344—20.4%
——6When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.45dCVE-2020-5974—20.4%
——6——CVE-2026-189954.3 MED20.4%
——6A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the file src/renderer/services/artifactParser.ts of the component MEDIA Path Handler. This manipulation causes information disclosure. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.25dCVE-2025-4671—20.4%
——6——CVE-2025-5340—20.4%
——6——CVE-2023-41079—20.4%
——6——CVE-2019-25356—20.4%
——6——CVE-2026-24810—20.4%
——6——CVE-2020-12346—20.4%
——6——CVE-2020-12302—20.4%
——6——CVE-2024-9751—20.4%
——6——CVE-2021-31240—20.4%
——6——CVE-2026-31955—20.4%
——6——CVE-2026-32634—20.4%
——6——CVE-2026-178154.3 MED20.4%
——6Insufficient policy enforcement in GuestView in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)34dCVE-2026-26286—20.4%
——6——CVE-2026-822878.1 HIG20.4%
——6Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions by reflecting any request origin in Access-Control-Allow-Origin responses while credentials are enabled. Attackers can issue credentialed cross-origin requests from any website to read analytics data, account information, and perform authenticated state-changing operations as the victim user.6dCVE-2025-71264—20.4%
——6——CVE-2026-177624.3 MED20.4%
——6Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)33dCVE-2025-4420—20.4%
——6——CVE-2022-49358—20.4%
——6——CVE-2026-619365.5 MED20.4%
——6Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.21dCVE-2026-25528—20.4%
——6——CVE-2026-411227.1 HIG20.3%
——6Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain a stored cross-site scripting vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability. Exploitation may lead to information disclosure, session theft, or client-side request forgery.60dCVE-2026-199714.7 MED20.4%
——6A flaw has been found in LB-Link WR1210M 1.0.3. This impacts the function main of the file /www/cgi-bin/backup.cgi of the component Backup Endpoint. This manipulation causes missing authentication. The attack is only possible within the local network. The vendor was contacted early about this disclosure but did not respond in any way.17dCVE-2026-177634.3 MED20.4%
——6Inappropriate implementation in GPU in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)37dCVE-2026-479415.4 MED20.4%
——6Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.10dCVE-2026-479455.4 MED20.4%
——6Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.10d